Bonjour,
Voila je possede mon petit serveur en SME 6.0.1 et depuis plusieurs jours un petit malin a scanner le port 22 avec des listes de logins et password.
Mon Password admin n'est pas tres simple a retenir et se compose de 8 caracteres et grace a SME6Admin j'ais recu une notification par SMS (via les EMails de SFR)d'une connexion en SSH sur le serveur.
Bon 10 minutes plus tard je me connecte et je change le password par un password a 16 caracteres ce qui occupera le prochain branleur qui passera sur mon serveur.
Question existe t'il des solutions qui permettent de gerer ce type d'attack a 2 euros?
Par exemple un RPM qui detecte des connexions en serie sur une periode de 5 minutes et qui pourrais fermer les ports SSH ou autre afin de s'autoproteger??
Merci
Richard
voici des log pour le fun
Nov 20 17:42:15 proliant sshd[6343]: Failed password for illegal user cip51 from 211.98.29.125 port 34510 ssh2
Nov 20 17:42:19 proliant sshd[6345]: Failed password for root from 211.98.29.125 port 34548 ssh2
Nov 20 17:42:22 proliant sshd[6347]: Failed password for illegal user noc from 211.98.29.125 port 34586 ssh2
Nov 20 17:42:26 proliant sshd[6349]: Failed password for root from 211.98.29.125 port 34623 ssh2
Nov 20 17:42:30 proliant sshd[6351]: Failed password for root from 211.98.29.125 port 34664 ssh2
Nov 20 17:42:33 proliant sshd[6353]: Failed password for root from 211.98.29.125 port 34704 ssh2
Nov 20 17:42:37 proliant sshd[6355]: Failed password for root from 211.98.29.125 port 34739 ssh2
Nov 20 17:42:41 proliant sshd[6357]: Failed password for illegal user webmaster from 211.98.29.125 port 34772 ssh2
Nov 20 17:42:47 proliant sshd[6359]: Failed password for illegal user data from 211.98.29.125 port 34819 ssh2
Nov 20 17:42:51 proliant sshd[6361]: Failed password for illegal user user from 211.98.29.125 port 34884 ssh2
Nov 20 17:42:54 proliant sshd[6363]: Failed password for illegal user user from 211.98.29.125 port 34929 ssh2
Nov 20 17:42:58 proliant sshd[6365]: Failed password for illegal user user from 211.98.29.125 port 34951 ssh2
Nov 20 17:43:01 proliant sshd[6367]: Failed password for illegal user web from 211.98.29.125 port 34999 ssh2
Nov 20 17:43:05 proliant sshd[6369]: Failed password for illegal user web from 211.98.29.125 port 35037 ssh2
Nov 20 17:43:09 proliant sshd[6371]: Failed password for illegal user oracle from 211.98.29.125 port 35068 ssh2
Nov 20 17:43:12 proliant sshd[6373]: Failed password for illegal user sybase from 211.98.29.125 port 35110 ssh2
Nov 20 17:43:16 proliant sshd[6375]: Failed password for illegal user master from 211.98.29.125 port 35138 ssh2
Nov 20 17:43:20 proliant sshd[6377]: Failed password for illegal user account from 211.98.29.125 port 35182 ssh2
Nov 20 17:43:24 proliant sshd[6379]: Failed password for illegal user backup from 211.98.29.125 port 35230 ssh2
Nov 20 17:43:30 proliant sshd[6381]: Failed password for illegal user server from 211.98.29.125 port 35253 ssh2
Nov 20 17:43:34 proliant sshd[6383]: Failed password for illegal user adam from 211.98.29.125 port 35318 ssh2
Nov 20 17:43:37 proliant sshd[6385]: Failed password for illegal user alan from 211.98.29.125 port 35359 ssh2
Nov 20 17:43:41 proliant sshd[6387]: Failed password for illegal user frank from 211.98.29.125 port 35404 ssh2
Nov 20 17:43:45 proliant sshd[6389]: Failed password for illegal user george from 211.98.29.125 port 35432 ssh2
Nov 20 17:43:49 proliant sshd[6391]: Failed password for illegal user henry from 211.98.29.125 port 35477 ssh2
Nov 20 17:43:53 proliant sshd[6393]: Failed password for illegal user john from 211.98.29.125 port 35509 ssh2
Nov 20 17:43:56 proliant sshd[6395]: Failed password for root from 211.98.29.125 port 35544 ssh2
Nov 20 17:44:00 proliant sshd[6397]: Failed password for root from 211.98.29.125 port 35588 ssh2
Nov 20 17:44:04 proliant sshd[6399]: Failed password for root from 211.98.29.125 port 35625 ssh2
Nov 20 17:44:08 proliant sshd[6401]: Failed password for root from 211.98.29.125 port 35658 ssh2
Nov 20 17:44:11 proliant sshd[6403]: Failed password for root from 211.98.29.125 port 35696 ssh2
Nov 20 17:44:18 proliant sshd[6405]: Failed password for test from 211.98.29.125 port 35735 ssh2